Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

101–110 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#102
post #78

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…

Just look at what Citron Research did to Shopify last year. They tanked the stock from $120 to $93 just based on false accusations that they put out in a "report".

Now Shopify is now closer to $150...so their plan worked.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#103
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

I can vet the guys who published this.

This is legit, and they haven't published anything that can be used maliciously.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#104
post #93
post #90

Earlier quoted context omitted.

You can consult the search bar at the bottom of the page to learn that I am 100% OK with immediate, uncoordinated disclosure. It's not what I personally do, but that's easy for me to say because I don't find these kinds of vulnerabilities. This isn't "shoot the hostages". The researchers didn't manufacture the vulnerabilities; AMD did. If 4 dudes in a basement can find exploitable driver vulnerabilities, so can 10 re…

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

I strongly disagree with the reasoning you're using here.

The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.

No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation for any vulnerability: the power switch.

Most of the time, most users have better non-patching mitigations than that. These vulnerabilities are all post-compromise privilege escalation flaws. Their exploitation is situational and most users can do things to eliminate the situation that enables their exploit.

You might not like the fact that end-users have to make hard, expensive choices about how to mitigate flaws. But if you think about it for just a second, you'll see that the idea that patches were saving them from this choice was fallacious. There is no reason to believe these 4 dudes were the only ones in the world capable of finding these flaws (the reality is that if they're the only ones who know about them, it's because the kinds of flaws they found simply aren't important enough to demand focused attention from others). All restricted disclosure does is prevent end users from making the choice for themselves.

I believe that as a general rule, we're better off when we have the most information available to us about vulnerabilities. Personally, I'd probably stop short of publishing exploit code. But other researchers that most of us respect a great deal in the abstract do not have that particular scruple, and some --- like the original Metasploit project --- made it a point to publish exploit code immediately, patch or no patch, to arm operators with information about their exposure.

This isn't an idle opinion. If there was working Usenet search in 2018, you could find me making approximately the same argument back in the 1990s, when I worked as a researcher at SNI, the world's first commercial vulnerability research lab.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#105
post #91
post #77

Earlier quoted context omitted.

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

So you believer in the absolute freedom of security vulnerabilities disclosures and security researchers should just do so at will?

Do you know that the general public are usually the ultimate victims and impacted by those vulnerabilities the most?

Especially Intel/AMD are corporations worth tens of billions monopolies in their fields, and if their CPUs with zero days unpatched and sample code and exploitation techniques out in the wild, what else are you gonna use on your desktop computers?

We've seen similar happened for Microsoft after Shadow Brokers's disclosure.[1] It's gonna be worse for hardware products as it's virtually impossible to retroactively fix silicons chips.

[1]: https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#106
post #98
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

These guys are essentially more black hat than white hat

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#107
post #103

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

I can vet the guys who published this. This is legit, and they haven't published anything that can be used maliciously.

The security flaws aren't really the issue. The way they did it seems like they have an interest to manipulate the stock.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#108
post #106
post #98

Earlier quoted context omitted.

These guys are essentially more black hat than white hat

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

Black hat isn't distinguished by failing to report vunlerabilities. It's distinguished by bad faith.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#109
post #106
post #98

Earlier quoted context omitted.

These guys are essentially more black hat than white hat

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

I think some here believe that the weapon here is financial; to trade the stock.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#110
post #105
post #91

Earlier quoted context omitted.

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

So you believer in the absolute freedom of security vulnerabilities disclosures and security researchers should just do so at will? Do you know that the general public are usually the ultimate victims and impacted by those vulnerabilities the most? Especially Intel/AMD are corporations worth tens of billions monopolies in their fields, and if their CPUs with zero days unpatched and sample code and exploitation techni…

What happened after the Shadow Brokers? Are we using dogs now to detect the Terminators?
Post reply on HN